STIIIZY Data Breach Settlement: Claims Due Sept. 10
At a glance
- Status
- Open
- Defendant
- STIIIZY, Inc.
- Settlement fund
- $2,950,000
- Claim deadline
- September 10, 2026
- No-proof cash option
- Yes — Option 1: pro-rata cash + 2 yrs credit monitoring/ID theft insurance (no documentation). Option 2: reimbursement of documented losses, up to $7,500 per individual. or up to 7500
- Max documented payout
- $7,500
- Administrator
- Eisner Advisory Group LLC
- Official site
- www.stiiizydatabreachsettlement.com
- Court
- United States District Court for the Central District of California
- Case number
- In Re: STIIIZY Inc. Data Breach Security Litigation, No. 2:25-cv-00490
Last verified July 16, 2026
Key dates
| Milestone | Date | What it means |
|---|---|---|
| Claim deadline | September 10, 2026 | Last day to file for a payment |
| Opt-out (exclusion) deadline | August 26, 2026 | Last day to leave the settlement and keep the right to sue |
| Objection deadline | August 26, 2026 | Last day to object to the terms |
| Final approval hearing | October 19, 2026 | When the judge decides whether to approve the settlement |
| Expected payout | Not yet scheduled | Payments are not sent until after final approval and any appeals |
Where to file
STIIIZY Data Breach Settlement is administered by Eisner Advisory Group LLC. The only place to file is the official settlement website:
File at the official sitewww.stiiizydatabreachsettlement.com
Filing is free. No legitimate settlement charges a fee to file a claim.
You cannot file on RecordingLaw.com. We are an independent publisher, not the settlement administrator, and we are not affiliated with any court, agency, or defendant.
STIIIZY, the California cannabis brand and dispensary operator, notified customers that their personal information was affected by an October 2024 data security incident. As of July 2026, a $2,950,000 class action settlement is open to resolve claims connected to that incident. Here is what the settlement covers, where the case stands right now, and what a realistic payout looks like.
What happened in the STIIIZY data breach
STIIIZY is a California-based cannabis brand and licensed dispensary operator. The company notified affected customers that their personal information was involved in a data security incident it identified in October 2024. The resulting litigation was consolidated into a single case, In Re: STIIIZY Inc. Data Breach Security Litigation, filed in the United States District Court for the Central District of California, case number 2:25-cv-00490.
The settlement resolves that litigation with a $2,950,000 common fund. It does not resolve every possible legal question about the incident itself, it resolves the claims that were brought in this case, and it does so through a negotiated payment rather than a trial.
Why a dispensary breach carries a risk a typical retailer breach doesn't
Licensed cannabis dispensaries in California are generally required to verify a customer's age and identity at the point of sale, which commonly means scanning or recording a government-issued ID such as a driver's license. That is a characteristic of how dispensary retailers keep records industry-wide, not a confirmed list of what STIIIZY's own systems held or what this specific incident exposed. STIIIZY has not published a detailed, itemized breakdown of the exact data elements involved in the October 2024 incident, so this page does not claim to know that list, and neither should you assume it from general reporting about dispensary breaches.
What is worth understanding is the category of risk. Because STIIIZY operates as a licensed dispensary, any customer record on file at a business like it characteristically links a real name to that person's status as a cannabis purchaser, on top of the usual identifiers like an address or date of birth. That combination raises concerns beyond ordinary identity theft. Depending on the person, evidence connecting a name to cannabis purchases can matter to an employer's background check, an immigration proceeding, a professional licensing board, or a federal firearms purchase, since cannabis remains federally restricted regardless of state legality. A credit freeze stops someone from opening a new account in your name. It does nothing to un-expose that kind of association. If you received a notice from STIIIZY, treat the specific list of data types in your own letter as the accurate record for you, not general assumptions about what dispensary breaches typically involve.
Where the case stands right now
As of July 2026, the STIIIZY Data Breach Settlement is open and accepting claims. The deadline to file a claim is September 10, 2026. The deadline to exclude yourself from the settlement or to object to its terms is August 26, 2026.
A federal judge still has to grant final approval before any money is paid out. That hearing is scheduled for October 19, 2026. No payout date has been set, and none will be until after the judge signs off and any objections are resolved. If you are looking for a date your payment arrives, that date does not exist yet.
Who is in the settlement class
The class is defined as individuals STIIIZY notified that their personal information was affected by the October 2024 data security incident. In practice, that means people who bought from STIIIZY or otherwise had information on file with the company, and whom STIIIZY identified in its own records as impacted and sent a notice to.
Class membership is based on STIIIZY's own records of who was affected, not on whether you personally remember receiving a letter or email. If you are unsure whether you are covered, the official settlement site lets you check using the identifying information referenced in your notice.
How much money can you actually get
Lead with the part of this settlement that does not require filling out a documentation packet: eligible class members can enroll in two years of credit monitoring and identity theft insurance at no cost, with no proof of loss required. If you do nothing else, that free benefit alone is worth claiming.
Alongside that free monitoring, claimants who choose this no-documentation path also receive a pro-rata cash payment. The settlement does not publish a fixed dollar estimate for that payment, so this page will not invent one. It is calculated by dividing a portion of the $2,950,000 fund, after fees, costs, and administration expenses are deducted, among everyone who files a valid claim, so the actual amount depends on how many people come forward.
If you had real, documented losses tied to the incident, such as fraud charges or costs you paid to deal with identity theft, you can instead claim reimbursement of those losses, up to a cap of $7,500 per person. That $7,500 figure is a ceiling, not a typical outcome, and it requires supporting records. Most class members who choose the no-documentation path will see a modest pro-rata payment, not a large one. Treat every number on this page, including the $7,500 cap, as an estimate subject to adjustment, not a guarantee.
What proof you need to file
For the no-documentation option, credit monitoring plus a pro-rata cash payment, you do not need to submit records. You attest that you are a class member and select that option.
For the documented-loss option, up to the $7,500 cap, you will need records connecting a specific, out-of-pocket loss to this incident, such as statements showing fraudulent charges or receipts for costs you paid to resolve identity theft. The more specific and dated your documentation, the stronger that portion of your claim.
How filing works
Filing happens on the official settlement website, and the deadline for either option, no-documentation or documented-loss, is September 10, 2026. A claims-made deadline like this one does not reopen after it passes.
If you plan to claim documented losses, start gathering your records now rather than waiting until the deadline is close. If you only intend to take the no-documentation cash and monitoring option, the process is simpler, but the same September 10, 2026 cutoff still applies.
If you're not sure you were affected, or you want to do more than file a claim
Whether or not you file, freezing your credit at all three bureaus, Equifax, Experian, and TransUnion, is free by federal law and is the single most effective step against someone opening new accounts in your name. It does not conflict with also enrolling in the monitoring this settlement offers; a freeze blocks new credit, monitoring watches your existing accounts and alerts you to activity, and the two work together rather than replacing each other.
If you notice suspicious activity on any account, or you want a personalized recovery plan, IdentityTheft.gov is the federal government's free resource for exactly that. You do not need to be part of any settlement to use it.
For other open recoveries like this one, RecordingLaw tracks active cases at its data breach settlement tracker.
Frequently Asked Questions
Is the STIIIZY data breach settlement still open?
Yes. As of July 2026, claims are open and must be filed by September 10, 2026. The deadline to exclude yourself or object is August 26, 2026.
What caused the STIIIZY data breach settlement?
The settlement resolves litigation over an October 2024 data security incident at STIIIZY, in which the company notified customers that their personal information was affected. It is pending in the U.S. District Court for the Central District of California, case number 2:25-cv-00490.
Who is eligible for the STIIIZY settlement?
You may be eligible if STIIIZY notified you that your personal information was affected by its October 2024 data security incident. Eligibility is based on STIIIZY's own records of who was affected, not on whether you recall getting a notice.
How much money will I get from the STIIIZY settlement?
It depends on which option you choose and how many people file. The no-documentation option adds a pro-rata cash payment on top of two years of free credit monitoring and identity theft insurance, while documented losses can be reimbursed up to $7,500. Both are estimates from a shared $2,950,000 fund, not guaranteed amounts, and most claimants should expect a modest pro-rata payment rather than the $7,500 ceiling.
Does the STIIIZY settlement include credit monitoring?
Yes. Class members who choose the no-documentation option can enroll in two years of credit monitoring and identity theft insurance at no cost, without submitting proof of loss.
Can I still opt out of or object to the STIIIZY settlement?
As of July 2026, yes, but not for much longer. The deadline to exclude yourself from the settlement or object to its terms is August 26, 2026.
When will STIIIZY settlement payments go out?
No payout date has been set as of July 2026. A judge must first grant final approval at a hearing scheduled for October 19, 2026, and no distribution timeline has been published beyond that.
Who is administering the STIIIZY data breach settlement?
Eisner Advisory Group LLC is administering the settlement through the official site, stiiizydatabreachsettlement.com. Some third-party coverage of this case has named a different administrator; the settlement's own site confirms Eisner Advisory Group LLC.
Does a STIIIZY data breach carry risks beyond typical identity theft?
Dispensary retailers characteristically collect a government-issued ID at the point of sale to verify age, which is a feature of the industry generally rather than a confirmed detail of exactly what this incident exposed. If your STIIIZY notice specified what data of yours was involved, treat that letter as the accurate record.
How to tell a settlement notice is real
Check the case name, case number, and court against the official settlement site. Go to that site directly instead of clicking a link in an email or text. Nobody legitimate will call, text, or email out of the blue asking for your Social Security number, bank account, or card details, and nobody will charge you to file. Report anyone who does at ReportFraud.ftc.gov.
Informational only. Not legal, tax, or financial advice, and not affiliated with any settlement.
RecordingLaw.com is an independent legal-information publisher. We are not a law firm, not a settlement administrator, and not affiliated with, endorsed by, or acting on behalf of any court, government agency, defendant, or claims administrator described on this page. Reading this page does not create an attorney-client relationship.
We do not process claims and we never collect your claim information. You cannot file a claim on RecordingLaw.com. To file, opt out, object, or check your status, use only the official settlement administrator identified above. We link to it for your convenience.
Filing a legitimate claim is free. No legitimate settlement or administrator will charge you a fee to file, or ask for your Social Security number, bank, or card details by unsolicited call, text, or email. If someone does, it is likely a scam. Report it at ReportFraud.ftc.gov.
Deadlines, amounts, and approval status change and are set by the court. We verify against the official administrator and court records, but confirm the current details on the official site before acting. Nothing here guarantees eligibility, a payment, or any amount. Settlement payments may be taxable. See IRS Publication 4345. and consult a tax professional. For advice about your specific situation, consult a licensed attorney in your state. Affiliate disclosure.
Sources and References
- California Attorney General, Data Security Breach Reporting Database(oag.ca.gov).gov
- IdentityTheft.gov, Federal Trade Commission identity theft recovery(identitytheft.gov).gov
- FTC Consumer Advice: Credit Freezes and Fraud Alerts(consumer.ftc.gov).gov
- IRS Publication 4345, Settlements, Taxability(irs.gov).gov
- STIIIZY Data Breach Settlement, Official Settlement Website(stiiizydatabreachsettlement.com)